How to permit the ISIS packet in ASA ?

Answered Question
Sep 16th, 2008
User Badges:

The ethertype of the ISIS is 0x83,Does the ASA support this type?how to let the hello or traffic pass the firewall in transperent mode?

thanks

Correct Answer by suschoud about 8 years 9 months ago

Hi,



The transparent mode security appliance does not pass CDP packets or IPv6 packets, or any packets that do not have a valid EtherType greater than or equal to 0x600. For example, you cannot pass IS-IS packets. An exception is made for BPDUs, which are supported.




Reference :



http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwmode.html#wp1198794




Please rate if helps.



Regards,

Sushil

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
suschoud Wed, 09/17/2008 - 04:47
User Badges:
  • Gold, 750 points or more

Hi,



The transparent mode security appliance does not pass CDP packets or IPv6 packets, or any packets that do not have a valid EtherType greater than or equal to 0x600. For example, you cannot pass IS-IS packets. An exception is made for BPDUs, which are supported.




Reference :



http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwmode.html#wp1198794




Please rate if helps.



Regards,

Sushil

Actions

This Discussion